CAS-004 Security Operations Practice Question
A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an attacker used DNS tunneling to exfiltrate data. Which THREE network traffic indicators would support this hypothesis? (Select THREE.)
⚠ Common exam trap
CAS-005 often tests the ability to distinguish DNS tunneling indicators from other attack indicators, causing candidates to select generic exfiltration signs like HTTP traffic or failed logins instead of DNS-specific anomalies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Large DNS response packets (greater than 512 bytes)
Option B is correct because DNS tunneling typically requires encoding data in DNS responses, which pushes packet sizes beyond the standard 512-byte UDP DNS limit and often forces TCP fallback or EDNS0 usage, making large DNS response packets a strong indicator. Option D is correct because tunneling tools encode exfiltrated data into subdomain labels, producing long, high-entropy, randomly generated subdomains that are atypical of legitimate DNS traffic. Option E is correct because DNS tunneling generates a high volume of queries from a single host as data is chunked and sent in many small DNS requests, so an unusual spike in query count from one internal host supports the hypothesis. Option A does not belong because failed login attempts indicate authentication attacks such as brute forcing, not DNS-based exfiltration. Option C does not belong because unencrypted HTTP to external IPs is a general web traffic observation and is not specific to DNS tunneling, which operates over port 53.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A sudden increase in failed login attempts
Why it's wrong here
Failed logins indicate authentication brute-forcing or credential attacks, not DNS tunnelling, which hides data inside DNS queries and responses. It is tempting because authentication failures are a common SIEM indicator, and would be the correct choice when investigating password spraying or account lockout activity rather than covert exfiltration.
- ✓
Large DNS response packets (greater than 512 bytes)
Why this is correct
DNS tunnelling encodes exfiltrated data into DNS records, inflating responses well beyond the 512-byte UDP limit and often forcing TCP fallback. Large response packets therefore satisfy the stem's requirement for network indicators supporting the DNS tunnelling hypothesis.
- ✗
Unencrypted HTTP traffic to external IPs
Why it's wrong here
DNS tunnelling hides exfiltration inside DNS queries and responses, so plaintext HTTP to external IPs indicates a different channel. It is tempting because unencrypted traffic exposes payloads, but that suits HTTP-based exfiltration. DNS tunnelling instead shows anomalous query volume, long encoded subdomains and TXT-record abuse.
- ✓
DNS queries for domains with long subdomains and random characters
Why this is correct
Tunnelling tools encode data into the query name itself, producing long, high-entropy subdomains that carry payload chunks to an attacker-controlled authoritative server. This satisfies the stem's requirement for a network indicator consistent with DNS-based exfiltration.
- ✓
An unusually high number of DNS queries from a single host
Why this is correct
Tunnelling generates far more DNS requests than normal host behaviour, as each chunk of exfiltrated data requires its own query. A single host issuing an unusually high volume of DNS queries satisfies the stem's requirement for an indicator supporting the DNS tunnelling hypothesis.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.